Alert Type

PSN - Product Support Notification
Low/NotificationSRN
Low/NotificationSRN

Product Affected

ACX, EX, MX, PTX, QFX, NFX, SRX, VMX, VRR, VSRX, JET, FUSION Platforms

Alert Description


Junos Software Service Release version 20.2R3-S4 is now available for download from the Junos software download site

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

Solution

Junos Software service Release version 20.2R3-S4 is now available.

20.2R3-S4 - List of Fixed issues

PR NumberSynopsisCategory: EX4300 PFE
1630616The ARP resolution may get failed on VRRP enabled interface
Product-Group=junos
On EX4300, ARP resolution against virtual IP on VRRP enabled interface may get fail with "no-arp-trap" is configured due to which service may get affected.
1630935Application of firewall filters might break connectivity towards the hosts on EX4300
Product-Group=junos
On EX4300 platforms except EX4300-MP/EX4300-48MP, once input/output firewall filters are applied to the interfaces under family ethernet-switching, it might result in disrupting the connectivity towards few hosts connected to the device and thus impacts the related traffic.
PR NumberSynopsisCategory: EX4300 Platform
1580829Some interfaces might be down after the power outage or power cycle
Product-Group=junos
On EX4300-VC platforms, after a power outage, some of the interfaces might be down when configured with no-auto-negotiation, and speed is configured, which might impact the traffic.
PR NumberSynopsisCategory: EX4300 Layer 2 implementation
1600029On EX4300 platform MAC addresses aging issue is seen
Product-Group=junos
On EX4300 platforms, some of the MAC addresses might not aged out specific to virtual chassis. When a LAG (aggregate interface) is configured and if any of the FPC member of virtual chassis has no interface part of LAG, then MACs learnt on the LAG interface may not aged out.
PR NumberSynopsisCategory: EX4300 Virtual Chassis
1624850Delay might be observed while establishing the virtual-chassis post upgrading or rebooting device
Product-Group=junos
On all EX4300 platforms except EX4300-48MP with virtual chassis ports using the DAC cables, there might be a delay in establishing the virtual-chassis post upgrading or rebooting the device.
PR NumberSynopsisCategory: EX2300/3400 PFE
1564941The DHCP client might not obtain IP address when dhcp-security is configured
Product-Group=junos
On EX2300 platforms, if enterprise Style (EP) and service provider (SP) style configurations are mixed on a trunk interface, the DHCP client under SP style configuration might not obtain IP address when dhcp-security is enabled on one of the trunk VLANs.
1616646PFE might crash due to deletion of storm control configuration for IFL in CLI which may lead to traffic loss
Product-Group=junos
On Junos EX and QFX platforms with storm control IFL entry, when deleting the storm control configuration in CLI PFE reboot might occur due to access of storm control IFL entry memory that was freed during deletion which might lead to traffic loss.
1627857Packet drop might be observed when L2PT is configured on transit device
Product-Group=junos
On ACX/EX/QFX Junos platforms with Q-in-Q setup in SP(Service Provider) style configuration, when L2PT (Layer2 Protocol Tunneling) is enabled on a transit switch, mac rewritten packets might get dropped on the transit device due to which protocol (for example, STP) convergence fails between the end nodes and thus L2PT breakage could be observed for service-VLANs included in the environment.
1632643Unicast ARP packets with the first four bytes of its destination MAC matching to system macs of a transit system gets trapped by the system
Product-Group=junos
On EX2300 platforms as transit switches, when no-arp-trap is enabled, if the ARP packets are unicast of which the destination MAC has upper four bytes matching to the system MAC, the ARP packets are not forwarded but trapped.
1633115Traffic loss for 20 sec on VC with AE link-protection when rebooting backup FPC
Product-Group=junos
On EX/QFX series Virtual Chassis (VC) with Aggregated Ethernet (AE) link-protection configured, traffic loss could be seen for around 20 sec when the traffic is passing through backup link and backup FPC is rebooted.
PR NumberSynopsisCategory: EX2300/3400 platform
1627673System time may not be updated after reboot on EX2300 platform
Product-Group=junos
System time may not be updated after reboot. Symptoms seen are: 1) After USB image installation, CLI is not working fine. 2) When DHCP persistence is configured with DHCP security and device reboots, the lease time values may show a high lease value post reboot.
PR NumberSynopsisCategory: QFX PFE CoS
1633827Unable to configure policer with "bandwidth-limit" more than 50G
Product-Group=junos
On EX4650 and on all QFX5k (except QFX5220 and QFX5770) platforms, a policer with a "bandwidth-limit" of more than 50G may not be configured for a 100G port.
PR NumberSynopsisCategory: QFX PFE MPLS
1607169MPLS VPN packets drop due to missing ARP entry on PE
Product-Group=junos
On QFX5K and EX4600 platforms, with Multiprotocol Label Switching (MPLS) over Integrated Routing and Bridging (IRB) interface on Provider Edge router (PE router), PE might not have any ARP resolution for MPLS forwarded Virtual Private Network (VPN) packets, resulting in reachability issue from remote Customer Edge (CE) or PE device.
1627002Traffic towards MPLS-Core is not rerouted to alternate port on QFX5k platforms
Product-Group=junos
On QFX5k platforms after active egress port is down, traffic is not rerouted to alternate port towards Multiprotocol Label Switching (MPLS)-Core.
PR NumberSynopsisCategory: CoS support on ACX
1633427The storm-control rate-limit might not work with VPLS policer under IFL
Product-Group=junos
On ACX5448 platforms, when storm-control rate-limit is configured on the physical interface along with the VPLS(Virtual Private LAN Service) filter and policer configured under attached IFL(logical interface), storm-control rate-limit might not get applied to the ingress traffic and hence entire traffic might get forwarded further unexpectedly.
PR NumberSynopsisCategory: JUNOS kernel/ukernel changes for ACX
1636222ACX5448 PEM overload alarm threshold is incorrect
Product-Group=junos
On ACX5448/ACX5448-D/ACX5448-M platforms with AC PEMs, PEM 0 or 1 can incorrectly report overload or underload alarms, due to input feed exceeding the maximum limit or below the minimum limit. This issue happens because Min and Max threshold for voltage monitoring is not correct. Logs are seen as below when this issue happens. %DAEMON-4: Receive FX craftd set alarm message: color: 2 class: 100 object: 101 slot: 1 silent: 0 short_reason=PEM 1 voltage overl long_reason=PEM 1 overload/underload id=218104165 reason=218103808 %DAEMON-4: Alarm set: Pwr supply id=218104165, color=YELLOW, class=CHASSIS, reason=PEM 1 overload/underload %DAEMON-4: Minor alarm set, PEM 1 overload/underload PEM[1] Over voltage issue [vin: 240011mV, vout:12062mV] send: yellow alarm set, device PEM 1, reason PEM 1 overload/underload send: yellow alarm clear, device PEM 1, reason PEM 1 overload/underload PEM[1] Over voltage issue [vin: 240011mV, vout:12062mV] send: yellow alarm set, device PEM 1, reason PEM 1 overload/underload
PR NumberSynopsisCategory: ACX Interfaces IFD, IFL, vlans, and BRCM init
1624761On ACX5000 Local fault and Remote fault signaling is not logged on /var/log/messages
Product-Group=junos
When an interface encounters link state change on ACX5000, Local fault or Remote fault information is logged in show interfaces command in CLI. This information is expected to be logged in /var/log/messages as well.
1627040ACX2k: Output packet statistics are not incremented on the unit even after configuring statistics.
Product-Group=junos
ACX2k: Output packet statistics are not incremented on the unit even after configuring statistics.
PR NumberSynopsisCategory: ACX GE, 10GE, PoE, IDT framers
1633226Speed 10m configuration error on ACX5048 and ACX5096 platforms
Product-Group=junos
On ACX5048 and ACX5096 platforms interface speed 10m is not supported on 1G interface. This issue was introduced due to a bug fix and it has been resolved with this PR.
PR NumberSynopsisCategory: This category is for Broadband Edge accounting related issue
1628139Memory leak may occur on PFED process when the flat-file-profile is configured with knob 'use-fc-ingress-stats'
Product-Group=junos
In a scaled Subscriber Service Accounting scenario(~32K IFLs), if flat-file-profile is configured with 'use-fc-ingress-stats' knob, the memory leak on PFED(Packet Forwarding Engine Daemon) process may occur and if it crosses 80% of the total allocated memory of the process, it may crash.
PR NumberSynopsisCategory: BBE Autoconfigured DVLAN related issues
1626558The autoconf might not work if the DHCPv4 Discover message has option 80 (rapid commit) ahead of option 82
Product-Group=junos
If in the client's DHCP discover packet there has option 80 ahead of option 82, the auto-configure feature can not extract the subscriber's ACI (Agent Circuit-ID) and ARI (Agent Remote-ID). This leads to authentication failure when creating the Dynamic VLAN interface where option 82 is requested.
PR NumberSynopsisCategory: BBE interface related issues
1629910The egress traffic on non-targeted iflset of subscribers might not be forwarded correctly over targeted AE interface
Product-Group=junos
In subscriber traffic across links over an aggregated Ethernet (AE) interface scenario, the egress data of subscriber applications (e.g. PPPoE/L2TP/MPLS/DHCP) attached logical interface sets (iflset, e.g. pppoe-iflset/demux-iflset) are configured at Layer 3 to handle many sets of subscriber queues respectively over one targeted-distribution enabled Layer 2 ifl of AE interface (e.g. ae-x/y/z.1). In some rare cases, if the member link/FPC of AE are flapped, the underlying ifd of the AE bundle might not be attached to iflset again. Then the egress traffic forwarding function of subscribers over the AE interface (e.g. traffic redistribution/CoS scheduling resources) might be impacted.
1633392The bbe-smgd process might crash after removing and adding a child link from AE interface
Product-Group=junos
On MX platforms enabled with dynamic-profiles for subscribers and the subscribers are configured over AE [Aggregate Ethernet] interface with targeted-distribution. When the child links of the AE interface are removed and then added, it could lead to bbe-smgd crash in the backup RE. This in-turn could affect the control plane subscriber services when the primary RE fails during such event.
PR NumberSynopsisCategory: BBE Statistics daemon & libraries
1625648The bbe-statsd crash might be seen in the LTS subscriber scenario
Product-Group=junos
In the L2TP tunnel switch (LTS) subscriber scenario, the bbe-statsd crash might be seen if the accounting configuration is enabled on MX Series platforms.
PR NumberSynopsisCategory: Bi Directional Forwarding Detection (BFD)
1599431Some BFD sessions stuck in Init state after FPC restart
Product-Group=junos
After a reboot or chassis restart, everything goes Up and is stable. However, after restarting FPC 3 a good number of BGP sessions never recover. The reason is BFD (see the piece of log below) show bfd session | except up Detect Transmit Address State Interface Time Interval Multiplier XX.XX.XX.XX Init ae-x/x/x 6.000 2.000 3 XX:XX Init xe-x/x/x 256.000 2.000 3 After restarting fpc(Flexible PIC Concentrators ), there is a delay of 12-15sec delay to receive the PIPE close message. Few sessions which are using AE interface may stuck in init state forever. Which may impact traffic.
PR NumberSynopsisCategory: Border Gateway Protocol
1599730rpd crash might be seen when NSR is enabled
Product-Group=junos
On all Junos and Junos Evolved platforms when nonstop routing (NSR) is enabled during route convergence then routing protocol daemon (rpd) might crash with a core there-by causing service impact on the device.
1600599Kernel crash might be observed on platforms having BGP configured with family L2VPN
Product-Group=junos
On all Junos OS and Junos Evolved platforms running Border Gateway Protocol (BGP) with Layer 2 VPN (L2VPN) scenario, kernel crash might be observed.
1620463The rpd may crash and restart when NSR is enabled
Product-Group=junos
On all Junos with NSR (nonstop routing) enabled the rpd crash and restart may occur when RPKI (Resource Public Key Infrastructure) records are being replicated between the primary and backup RE (Routing Engine) and some of the records are withdrawn over the RPKI session.
1626367Time delay to export prefixes to BGP neighbors might occur post applying peer-specific BGP export policies
Product-Group=junos
On all Junos and EVO Platforms, when BGP export policies were changed from deny all to the peer-specific export policies, it might take several hours for the RPD/BGP to finish the export evaluation.
1626756Multipath route with List-NH which has Indirect-NH as members fails into BGP-LU
Product-Group=junos
"RT-multipath route with List-Next-hop which has Indirect-Next-hop as members" is unable to advertise into BGP-labeled-unicast address family. This scenario could happen in Carrier's Carrier (CsC) VRF which is also the reported case.
1635700The BFD session might be down when multiple addresses of same subnet are configured
Product-Group=junos
In the single-hop BFD of BGP scenario, when multiple addresses of the same subnet are configured on the interface of the BFD session, the BFD session might be down.
PR NumberSynopsisCategory: BBE Remote Access Server
1625858Radius CoA (Change of Authorization) NAK may not be sent with the configured Source Address in a virtual-router environment
Product-Group=junos
On all Junos, when running a radius server in multiple routing instances, the CoA NAK messages uses the interface address instead of the configured source address for non-existent sessions. This issue happens when the Radius server is configured in different virtual routers with different settings.
1626718ESSM sessions may get terminated in Radius as class attribute has got corrupted after performing ISSU
Product-Group=junos
When the ESSM (Extensible Subscriber Services Manager) service is getting created on existing subscriber session, the class attribute is wrongly formed. This happens when Radius sends class attribute in access-accept messages after performing ISSU.
PR NumberSynopsisCategory: bras licensing prs
1573289Scale-subscriber license might be not updated properly on the backup RE which leads to "License grace period for feature scale-subscriber(44) is about to expire" alarm after GRES
Product-Group=junos
In a rare scenario spurious scale-subscriber license violation may be raised on the new backup Routing Engine shortly after GRES switchover. It will lead to "License grace period for feature scale-subscriber(44) is about to expire" alarm if another GRES switchover is performed.
PR NumberSynopsisCategory: MX Platform SW - FRU Management
1571274Interfaces might fail to come up on MX240, MX480 and MX960 routers
Product-Group=junos
On MX240, MX480 and MX960 routers, if any I2c issue occurs on the device while rebooting that might cause midplane IDEEPROM read failure, then interfaces might fail to come up. When this issue happens, the error is only logged and no alarm is raised. This might cause unexpected impact.
1583060Certain line cards might lose fabric connectivity after removing an MPC showing I2C errors
Product-Group=junos
On chassis with MPC1/MPC1E/MPC2/MPC2E/MPC-3D-16XGE/MPCE-3D-16XGE-SFPP line cards, those line cards might lose fabric connectivity if another MPC of any type fails to be offlined because of I2C errors and must be hard removed. This can impact traffic flowing through those line cards. This does not affect normally functioning cards that are removed even if not properly offlined via the CLI. It also does not affect other MPC cards than the specific ones listed.
1634164Slow chassis memory leak may occur when chassisd related configuration change is committed
Product-Group=junos
On MX platforms, every commit routine may leak some memory in chassisd process. Over a long period of time if the total process heap memory usage goes above 3 GB approximately, chassisd may core and restart.
PR NumberSynopsisCategory: CFM
1620536OAM CFM session doesn't come Up if ERPS configured and CFM control traffic uses the same VLAN as ERPS control traffic
Product-Group=junos
Ethernet Ring Protection Switching (ERPS) is a ring protection scheme for Ethernet networks When EPRS and Connectivity Fault Management(CFM) are configured together. CFM packets will be dropped, hence, CFM session won?t come up
PR NumberSynopsisCategory: Device Configuration Daemon
1609838SNMP_TRAP_LINK_UP & SNMP_TRAP_LINK_DOWN trap might be seen while activating and deactivating firewall filters
Product-Group=junos
Unexpected LINK_UP/LINK_DOWN messages on vme interface might be seen in the syslog as part of config update on firewall filter. This issue is ONLY seen when vme interface is not configured, but not seen when vme interface is configured. And This issue only happens when virtual chassis is configured on the platform like EX Series or QFX Series Virtual Chassis.
PR NumberSynopsisCategory: Covers Application classification workflows apart from custo
1574056srxpfed/flowd might crash when deactivating and activating application-identification based policies /application-services configurations on SRX platforms
Product-Group=junos
On SRX platforms, memory is exhausting when the device is processing heavy traffic load or any configuration changes. Due to this, srxpfed/flowd might crash while deactivating and activating application-identification based policies/application-services configurations. This crash might cause temporary traffic loss.
1613516For apps getting classified on first packet, the volume update syslog is not getting generated.
Product-Group=junos
On Junos 21.3R1 release, due to the default enablement of PMI(Power Mode IPSec) express path at FLOW end, for apps getting classified on first packet, the volume update log is not getting triggered. Workaround is to disable PMI using config : "set security flow power-mode-disable".
1625364Coredumps might be reported on installing IDP security package
Product-Group=junos
On SRX platforms, when installing IDP sigpack, it might impact SRXPFE core file generation. It is a memory corruption issue.
PR NumberSynopsisCategory: Covers custom app
1628202The error might be seen after configuring a unified security policy allowing some app categories
Product-Group=junos
On SRX platforms, after committing the configuration of a unified security policy with some app categories, an error might be seen. Due to this unified security policy configuration might get failed.
PR NumberSynopsisCategory: EA chip ( MQSS SW issues )
1503705Traffic blackhole due to not disable-pfe in case of FO/WO checksum errors
Product-Group=junos
On MX platforms with MPC7/8/9/10/11, MX204/10K, EX92 or SRX5k with IOC4, in case of FO/WO errors, CMERRORs should be invoked and Major Alarms should trigger disable-pfe action. However, this does not happen. The following fixed has been made: 1. If WO/FO packet errors are seen in the continuous 3 periodic polling and the error packet count exceeds the threshold, raise a MAJOR CMERROR.Otherwise, display a syslog message. 2. Add VTY commands to display the WO/FO packet error interrupts.
PR NumberSynopsisCategory: Lacp related problems and issues.
1636093Some daemons might get stuck when snmpd is at 100% CPU utilization
Product-Group=junos
On all Junos and EVO platforms, when snmpd is at 100% CPU utilization and some daemons are trying to raise an SNMP trap, these daemons might get stuck which results in unbaling to handle any incoming corresponding packets and unbaling to response to any CLI commands.
PR NumberSynopsisCategory: eventd, syslog infra issues
1611885Master-eventd process might go down when syslog configuration is misconfigured
Product-Group=junos
On all Junos Operating System Evolved(EVO) based platforms with misconfigured syslog, master-eventd process might go down.
PR NumberSynopsisCategory: EVPN control plane issues
1600310Bridge mac-table learning entries might not be as expected for the EVPN-MPLS routing instance
Product-Group=junos
When using the logical tunnel (lt-) interface to stitch EVPN-MPLS and EVPN-VxLAN, bridge mac-table learning entries might not be as expected for the EVPN-MPLS routing instance. This is due to the AD (Auto-Discovery) route per ESI with VxLAN encapsulation community which is ignored on MPLS routing instance.
1629953Removing knob "es-label-oldstyle" does not take effect if it is the only knob configured under the protocol EVPN
Product-Group=junos
On MX, QFX, and EX series platforms with EVPN enabled, removing knob "es-label-oldstyle" does not take effect if it is the only knob configured under the protocol EVPN.
PR NumberSynopsisCategory: EX driver issues
1600291The SFP-T port might stop forwarding traffic on EX4600 platforms
Product-Group=junos
On EX4600, after performing an upgrade, the peer device is rebooted, the peer interface is disabled/enabled or rebooting EX4600, then the SFP-T port on EX4600 might remain in up state but could not forward traffic.
PR NumberSynopsisCategory: Express PFE including evpn, vxlan
1620924EVPN-VXLAN Type5 traffic might get failed on the Spine device of QFX10K
Product-Group=junos
In the EVPN-VXLAN scenario on QFX10002/08/16/QFX10002-60C platforms, when a route destination is reachable over more than one type-5 tunnel, in transient cases traffic on the type-5 tunnels is dropped.
PR NumberSynopsisCategory: Enhanced Broadband Edge support for firewall
1626091The bbe-smgd might crash on backup RE after ISSU/GRES
Product-Group=junos
On all Junos platforms with BNG enabled, after performing GRES or ISSU if a family is bouncing in a dual-stack scenario, then bbe-smgd might crash on backup RE and the traffic might get impacted if any switchover takes place.
PR NumberSynopsisCategory: Express ASIC interface
1582200The FEC91 mode might not get enabled automatically for QSFP28-SR4 SFP used on WAN interface
Product-Group=junos
On PTX3000 and PTX5000 with QSFP28-SR4 optics, the FEC (Forward Error Correction) mode FEC91 might not get enabled automatically if the FEC mode is explicitly configured and deleted previously. This might impact the traffic on the affected interface.
PR NumberSynopsisCategory: Internet Group Management Protocol
1607493Multicast traffic might be duplicated on subscriber interface on MX platforms
Product-Group=junos
On MX platforms with distributed IGMP enabled, if a non-bbe junos interface joins the same multicast group as the subscriber interface followed by GRES/NSR switchover, then multicast traffic might be duplicated on subscriber interface.
PR NumberSynopsisCategory: Fast Ethernet interfaces
1613430Static route might not work on vSRX
Product-Group=junos
On vSRX instance instantiated in Google Cloud, static route might not work.
PR NumberSynopsisCategory: Integrated Routing & Bridging (IRB) module
1623262Host generated IPv4 traffic sent over IPv6 next-hop with IRB interface might get dropped
Product-Group=junos
On all Junos platforms that support IRB(Integrated routing and bridging), when host originated IPv4 traffic is sent over IPv6 next-hop with IRB interface, the traffic might get dropped because of ether-type mismatch. This is because the ether-type field in L2 header is set to IPv6 (instead of IPv4) always due to the IPv6 next hop.
PR NumberSynopsisCategory: ISIS routing protocol
1633858IS-IS database may not be synchronized in some multiple areas scenario
Product-Group=junos
On all platforms with IS-IS multiple areas scenario, if the knob "flood-group" is enabled, IS-IS Databases may not get synchronized between areas after clearing the IS-IS DB or making the DB change in any other way. This is because when link-state packet (LSP) is fragmented, only the first packet has the area ID list (for flood-group matching), while the rest of the fragmented LSPs do not have that list, which will result in these packets not being flooded, so that ISIS will not work properly. Note: Flood Group is a feature of IS-IS, used to limit link-state packet data unit (PDU) flooding over IS-IS interfaces. When a link-state packet (LSP) that is not self-originated will be flooded only through the interface belonging to the flood group that has the configured area ID in the LSP. This helps minimize the routes and topology information, thus ensuring optimal convergence.
PR NumberSynopsisCategory: jdhcpd daemon
1618306The jdhcpd process started spiking and DHCP become unresponsive if modifying the configuration to add "override always-write-giaddr" and removed "forward-only"
Product-Group=junos
On EX platforms with DHCP enabled, if the configuration modified to add "override always-write-giaddr" and remove "forward-only" to move from stateless dhcp relay mode to stateful, jdhcpd process starts spiking and DHCP become unresponsive.
1620461Circuit-id handled incorrectly with backup node for ALQ with Topology discover configured
Product-Group=junos
Topology Discovery using mapping between Local and Remote Incoming Interface or DHCP Packet Receiving interface on Remote ALQ (Active-leasequery)peer is used to host subscribers.The mapped Remote Incoming Interface is used inside Option-82 and this will conflict with the circuit-id of the incoming DHCP packet on DHCP RELAY-1 and circuit-id of option-82 is over written leading to lose of information.
1625011The jdhcpd process crashes in DHCP/DHCPv6 environment
Product-Group=junos
On MX platforms, the jdhcpd process(DHCP daemon) might crash and dump core files in a DHCP/DHCPv6 (Dynamic Host Control Protocol) environment when the device is configured as a relay agent or server with 'active-leasequery. This might lead to subscriber termination and DHCP relay binding state of the terminating subscriber shows as 'Release' state.
1625604Option 82 might not be attached on DHCP request packets
Product-Group=junos
On Junos and EVO platforms, Option 82 enabled on Dynamic Host Configuration Protocol (DHCP) relay device might not be attached on DHCP request packets. In the end, DHCP request packets could not be forwarded to DHCP server. Without IP address assigned, DHCP clients could not access the network.
PR NumberSynopsisCategory: jl2tpd daemon
1596972"show services l2tp tunnel extensive", "show services l2tp session extensive" and "show subscribers accounting-statistics" commands do not work on LTS
Product-Group=junos
In a subscriber management environment CLI commands "show services l2tp tunnel extensive", "show services l2tp session extensive" and "show subscribers accounting-statistics" do not work on LTS (L2TP tunnel switch).
1629104L2TP tunnels may go down and not able to re-establish after restarting the bbe-smgd process
Product-Group=junos
On MX configured as L2TP access concentrator (LAC), if the bbe-smgd process is restarted when L2TP tunnels are getting down (e.g., L2TP tunnel will get down due to retransmission timed out caused by loss of IP connection between LAC and LNS) and later on the same tunnels are selected to tunnel new subscriber sessions, these L2TP tunnels may be stuck in down state and not be able to re-establish. The issue could cause the subscriber to lose connectivity. This is a timing issue.
1630150Tunneled subscribers may be stuck in terminating state in L2TP subscriber scenario
Product-Group=junos
On all MX platforms that support enhanced subscriber management (Next Generation Subscriber Management) with Layer 2 Tunneling Protocol (L2TP) subscriber scenario, L2TP subscribers may be stuck in terminating state if the L2TP subscribers try to login.
PR NumberSynopsisCategory: Application aware Quality-of-Service
1640768Configuration change during AppQoS session might result in PFE crash with flowd core
Product-Group=junos
On SRX/NFX platforms supporting Application Aware Quality Of Service (AppQoS), when the session is in process by AppQoS module and if any configuration change is pushed to PFE at the same time, PFE might crash with flowd core resulting in the traffic outage. Issue could be recovered by disabling AppQoS. It could be a rare timing issue.
PR NumberSynopsisCategory: Firewall Authentication
1626667The authentication delay might occur upto 60 secs if same user authenticates
Product-Group=junos
UAC(Unified Access Control) authentication delay upto 60 sec will be seen to pass authenticated traffic if same source IP address authenticates.
PR NumberSynopsisCategory: Flow Module
1573842The flowd/srxpfe process might crash when clearing the TCP-Proxy session
Product-Group=junos
On the SRX platforms, the flowd/srxpfe process might crash when clearing the TCP-Proxy session. Traffic loss might be seen during the flowd/srxpfe process crash and restart.
1619321Security traffic log display service-name="None" for some application
Product-Group=junos
On SRX series devices, the expected service name for some application does not display in security traffic log, however service-name="None" is displayed.
PR NumberSynopsisCategory: flow ha module
1624262SPU might become offline on standby node after failover in SRX cluster
Product-Group=junos
On SRX5400, SRX5600 and SRX5800 platforms configured in chassis cluster, when the primary node is rebooted, it triggers a failover. Services Processing Unit Central Point(SPU CP) on the new standby node becomes offline which causes HA in abnormal state. Core files are generated on the new standby node.
PR NumberSynopsisCategory: High Availability/NSRP/VRRP
1606724Secondary node in a chassis cluster might go into reboot loop on SRX platforms
Product-Group=junos
On SRX1500/4100/4200, the secondary node in a chassis cluster might go into reboot loop after RG0 (redundancy-group 0) failover and secondary node is rebooted manually.
PR NumberSynopsisCategory: Firewall Network Address Translation
1631815New persistent NAT or normal source NAT sessions might fail due to noncleared aged out sessions
Product-Group=junos
On high end SRX platforms with Central Point (CP) architecture and Services Processing Units (SPUs), if configured with all these features "persistent NAT, hairpin, source NAT", persistent NAT sessions might get stuck and aged out Persistent NAT sessions might not get cleared, due to which the new persistent NAT or normal source NAT session might fail.
PR NumberSynopsisCategory: Firewall Policy
1618025Redundancy might get affected in SRX Chassis Cluster scenario
Product-Group=junos
On SRX5000-Series with Chassis Cluster configured, there might be a redundancy issue observed. This happens when node master-ship changes, Network Security Daemon (NSD) reconnects to other node's Packet Forwarding Engine (PFE). An error in re-connection leads to this issue.
PR NumberSynopsisCategory: IPSEC/IKE VPN
1574409The SRXPFE process might crash and generate a core file when IPsec VPN is used
Product-Group=junosvae
On SRX4000 and SRX5000 Series devices, the SRXPFE process might crash and generate a core file when IPsec VPN is configured.
1627557Traffic over IPSec tunnels may be dropped post control link failure
Product-Group=junos
After control-link failure, the traffic over IPSec tunnels might be dropped.
1638437The kmd process might crash if the IKE negotiation fragment packets are missed during initiating an IKE SA rekey
Product-Group=junos
If IPsec IKEv2 is used and IKE negotiation fragment packets are missed during initiating an IKE SA rekey, the kmd process might crash. There will be temporary IPSec traffic interruption until the issue is restored automatically.
PR NumberSynopsisCategory: Security platform jweb support
1629978skip to jweb not working for srx300
Product-Group=junos
The J-Web setup wizard may not function correctly on SRX300 and SRX320 devices. The work around is to perform initial configuration manually.
PR NumberSynopsisCategory: Layer 2 Circuit issues
1626219The rpd process might crash during ISSU if the auto-sensing knob is enabled for l2circuit
Product-Group=junos
On all platforms which support the In-Service Software Upgrade (ISSU) feature, if the auto-sensing knob is enabled for l2circuit, the routing protocol daemon (rpd) might crash while performing ISSU. Traffic loss might be seen when the rpd is down and service can recover after rpd comes back up.
PR NumberSynopsisCategory: Layer2 forwarding on EX/NTF/PTX/QFX
1626714Broadcast traffic might not be forwarded to LT interface in VPLS routing instance after LT interface is deleted then added back
Product-Group=junos
On MX platforms, when Logical Tunnels (LT) interface is used for VPLS, VPLS broadcast traffic might not be forwarded to LT interface properly after deleting the LT interface adding it back, which might cause LT interface missing from VPLS flood topology and eventually affects VPLS communication.
1629678The l2ald might be stuck in "issu state" when ISSU is aborted
Product-Group=junos
On all Junos platforms, when Unified In-service Software Upgrade (ISSU) is aborted, Layer 2 Address Learning Daemon (l2ald) may not be able to read 'issu abort' notification and l2ald might be stuck in 'issu state' and l2ald will not process new events while in 'issu state'.
PR NumberSynopsisCategory: SW PRs for MPC10E Interfaces
1638410PFE might get stuck after 100G/400G interface flaps
Product-Group=junos
On Junos platforms equipped with MPC10E/MPC11E/LC2301/MX10K-LC9600 line cards, when any 100G/400G interface with high priority class-of-service scheduler configuration flaps, it might result in series of error messages during high traffic flow. Eventually this would result in PFE-disable action, impacting the related traffic. However, the issue could be recovered after FPC reboot.
PR NumberSynopsisCategory: Multicast for L3VPNs
1536903Stale PIM (S, G) entry might be seen in certain conditions under MVPN scenario
Product-Group=junos
On all Junos platforms with MVPN scenario, stale PIM (S, G) state might be seen when there are no local/remote receivers and the multicast source is inactive. Only stale PIM entry will be seen, and it doesn't impact MVPN service or functionalities.
PR NumberSynopsisCategory: MX104 Software - Chassis Daemon
1626486The chassisd might crash on MX104
Product-Group=junos
On the MX104 platform, when 'Invalid Chassis Model' occurs in the chassisd daemon, the chassisd might crash which might lead to interfaces down and automatic recovery. The fix is to solve avoid this chassisd core during 'Invalid Chassis Model' scenario.
PR NumberSynopsisCategory: Neo Interface
1621286Flapping of all ports in the same PFE may cause PFE to be disabled
Product-Group=junos
On MPC1, MPC1E, MPC2, MPC2E, MPC-3D-16, EX9200-40T, EX9200-40F, and EX9200-40F-M line cards and in a very rare situation, all ports from the same Packet Forwarding Engine going down may cause error of mqchip_disable_ostream timeout. When this error is seen, a temporary host loopback path wedge error may occur and trigger disable-pfe. The wedge can be cleared by itself, but the disable-pfe needs a FPC reboot to recover.
PR NumberSynopsisCategory: FreeBSD Kernel Infrastructure
1570148A false error related to insufficient space might appear while installing a Junos image that is corrupted
Product-Group=junos
On all Junos platforms, the upgrade might fail with a false error related to insufficient space when trying to install Junos from a corrupted package.
1581171The upgrade might fail when the space is enough for the new Junos file but is tight
Product-Group=junos
On all platforms with FreeBSD 11 or 12 based Junos, the upgrade might fail with the message "Error: not enough space to unpack " when the space is enough for the new Junos file but is tight. The issue is because space_available uses K bytes while space_required uses byte when calculates the space. The space_required might become bigger than space_available even when the real space_available is bigger than the space_required. Hence the message "Error: not enough space to unpack " is seen during the upgrade.
1601904The process rpd may slip due to a FreeBSD defect
Product-Group=junos
The process rpd may slip due to a FreeBSD defect. See [FreeBSD id=227689](https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=227689) for more information.
1639991Recovery snapshot might fail if OAM volume is already mounted
Product-Group=junos
Recovery snapshot might fail with the error "The OAM volume is too small to store a snapshot" if OAM volume is already mounted.
PR NumberSynopsisCategory: Kernel Tunnel Interface Infrastructure
1621696Traffic loss can be seen on the new master RE post GRES
Product-Group=junos
On all Junos platforms with GRE (Generic Routing Encapsulation) configuration, when we disable the gr interface on master RE and enable it on new master RE post GRES, traffic loss can be seen on the new master RE.
PR NumberSynopsisCategory: Express Chip L3 software
1598309The unilist nexthop might get stuck after interface flap on PTX/QFX10K
Product-Group=junos
On PTX/QFX10K platforms, some of the unilist nexthops might get stuck after interface flap, the issue might still exist even after FPC or rpd reboot.
1625988The knob "no-incoming-port" is not applied after reboot on QFX10002/QFX10008 platforms
Product-Group=junos
On QFX10002/QFX10008 platforms, "set forwarding-options enhanced-hash-key inet no-incoming-port" is not applied after rebooting system. The "no-incoming-port" knob is still present in configuration but it is not active when looking at the output of show commands.
PR NumberSynopsisCategory: vMX Data Plane Issues
1641119IPv4 and v6 packet header corruption could happen with some sampling scenario
Product-Group=junos
On vMX/MX150/NFX150 platforms, when sampling is enabled on input WAN interfaces and the sampled packet go out through a GRE tunnel, IPv4/6 header corruption may happen. Due to IP header corruption, remote router reports L3 incompletes at receiving interface.
PR NumberSynopsisCategory: Protocol Independant Multicast
1630144The multicast forwarding cache might not get updated after deactivating the scope-policy configuration
Product-Group=junos
On all Junos and EVO platforms with multicast setup, the multicast forwarding cache might not get updated after deactivating the scope-policy configuration. This could result in the PIM register process to be incomplete and further multicast traffic to be dropped.
PR NumberSynopsisCategory: vMX Platform Infrastructure related issue tracking
1537729MX150 Unexpected Behavior after using the command request system software validate
Product-Group=junos
'request system software validate' command is disabled currently from 19.4 and above. Customer can validate the same using 'request system software add'.
PR NumberSynopsisCategory: VRR (Virtual Route Reflector) for MX
1635950vRR VM might establish its identity as "Olive" after a CLI s/w upgrade
Product-Group=junos
vRR VM might come up as Olive after a CLI sw upgrade using junos-install-mx* package if the XML used to spawn the VM didn't have SMBIOS entry "VRR".
PR NumberSynopsisCategory: Periodic Packet Management Daemon
1599751rpd core might be observed due to memory corruption
Product-Group=junos
On all Junos and Evo devices, when connection between Internal Junos Modules (Routing Module & Periodic Packet Manager Module) resets, data structure representing that connection is not completely reset/freed. Due to this next time, when the connection is re-established, there is a possibility of re-using the old/stale data structure and this could lead to memory corruption and thereby rpd core.
PR NumberSynopsisCategory: Chassis mgmt for all QFX systems - chassis MIB, alarms, CLI
1584902The the QFX5000 and QFX10000 lines of switches might hang for some time after reboot
Product-Group=junosvae
On the QFX5000 and QFX10000 lines of switches, during reboot in certain instances the device might get into a state where the Junos virtual machine hangs until the NMI is triggered and reboots fully. The system recovers after approximately 30 minutes.
PR NumberSynopsisCategory: QFX platform fabric mgmt for Express ASIC chip
1559725QFX10000-60S-6Q line card takes more than 15 mins to boot up after Panic or Watchdog reboot has been triggered
Product-Group=junosvae
On QFX10000-60S-6Q line card on QFX10K platforms, during a reboot which is triggered by line card Linux Panic event or CPU Watchdog event, it may sometimes take more than 15 mins to come up.
1577315The port might not get brought down immediately during some abnormal type of line card reboot on the QFX10000 line of switches
Product-Group=junos
On the QFX10000 line of switches, if some system internal error is encountered (e.g., kernel software fault), it may result into some abnormal types of line card reboot. The port might not get brought down immediately after the reboot starts. This issue leads to traffic being silently dropped or discarded.
PR NumberSynopsisCategory: QFX L2 PFE
1484336The dcpfe might crash on platforms with auto-channelization enabled
Product-Group=junos
On QFX Series and EX Series switches with auto-channelization support, an optic speed mismatch connection might cause the auto-channelization to get into an infinite loop trying to match a proper speed. In this case, due to some memory leaks, the resources get exhausted, resulting in system crash. The traffic gets disrupted when the system dcpfe restarts.
1628845QFX5120VC : Restarting one of the FPCs may cause traffic loss in QFX VC scenario
Product-Group=junosvae
On QFX5120 with the Virtual Chassis (VC) scenario, when traffic coming in master FPC and going out from backup FPC, reboot the backup FPC, the master FPC still thinks the backup link is present, and show lacp interface also continues showing the backup link as collecting / distributing. Therefore, master FPC continues sending the echo reply through the backup link which fails since the backup is powered off, which might lead to traffic drop.
1633452The FBF filtered VLAN traffic will not be passed properly to the forwarding routing instances over AE interfaces on QFX5K/EX4600/EX4650 platforms
Product-Group=junos
On QFX5K/EX4600/EX4650 platforms with IPv4 Filter-based forwarding (FBF) scenario, when IPv4 FBF is used with 802.1Q VLAN tag enabled layer-3 AE interfaces, the VLAN filtered configuration enabled by FBF filter will be stored in the VLAN filter processor (VFP) ternary content addressable memory (TCAM). But, in some cases of adding/deleting the configuration of the routing instances (then routing-instance) in FBF filter, the stale allocated entries in VFP TCAM might not be deleted from the system, the memory slices of VFP TCAM will be exhausted until it is run out. Finally, there are not enough memory slices left to store the VLAN filtered information for the forwarding routing instances, then the FBF filtered VLAN traffic will not be forwarded correctly since the FBF filters might not be programmed/processed on the system.
1637249Configuring L2PT on a transit switch in a Q-in-Q environment breaks L2PT for other S-VLANs
Product-Group=junos
When L2PT (Layer2 Protocol Tunneling) is enabled on a transit switch using SP style configuration, protocol convergence between end nodes might fail.
1638619Targeted broadcast or WOL feature may not work on QFX 5k platforms
Product-Group=junos
On QFX platforms, Wake On LAN(WOL) feature stops working as the affected platforms erroneously process such packets. This might cause a blackhole in the network for such traffic.
PR NumberSynopsisCategory: QFX L3 data-plane/forwarding
1608610FPC might crash post firewall filter configuration changes in QFX platforms
Product-Group=junos
On QFX5110/5120 platforms with VXLAN routing scenarios, FPC might crash when there is a change in firewall filter configuration which is applied on IRB. This issue might not affect the 20.3R1 version.
1631771Inner VLAN might be stripped off when input-native-vlan-push is disabled
Product-Group=junos
On QFX platforms, in Q-in-Q scenario when 'input-native-vlan-push' knob is disabled inner Virtual LAN (VLAN) might be stripped off if it matches the outer VLAN. Traffic drop might be observed in this scenario.
PR NumberSynopsisCategory: QFX EVPN / VxLAN
1612905Arp resolution for data traffic received over Type5 might fail
Product-Group=junos
Arp resolution for Data traffic received over Type5 might fail if the VNI ussed for decap for a given tunnel is also used for Encap VNI for another tunnel. When Encap VNI for a tunnel is created first followed by Decap VNI(same vni) for another tunnel we fail to update the routing instance needed for Decap.
1624925QFX5K log messages: fpc0 SRIRAM Tx VxLAN Ucast: ifd_out = vtep dst_gport is (c00000X) so do not process pkt further
Product-Group=junos
Log messages "fpc0 SRIRAM Tx VxLAN Ucast: ifd_out = vtep dst_gport is (c00000X) so do not process pkt further" can show up on QFX5K switches (where X = different values). These are harmless messages.
1635347Data might not be exchanged via EVPN-VxLAN domain
Product-Group=junos
On QFX5000 series platforms (i.e., QFX5100 and QFX5200 etc) running Junos system ONLY, if VLAN ID configured on Leaf devices is different, traffic from different end-hosts might not be transported via Ethernet VPN and Virtual Extensible LAN (EVPN-VxLAN) domain. There is a service impact when this issue happens.
1636950Traffic blackhole might be observed when STP is configured in VxLAN environment
Product-Group=junos
On QFX platforms in VxLAN scenario, if STP is enabled on all the interfaces of the switch, ethernet table might not get populated to locally connected devices resulting in traffic blackhole.
PR NumberSynopsisCategory: QFX VCCP
1600398The VCP might not form adjacency after rebooting the master FPC in VC scenario
Product-Group=junos
In the QFX5100-48S-6Q Virtual Chassis when there's more than one VCP (Virtual Chassis Port) used, after rebooting the master FPC, the VCP might fail to form VCCP adjacency. The affected version and fixed version for QFX5100-48S-6Q are listed as below: 1. For QFX5100-48S-6Q with QFX5e image starting from 17.3 and later releases are affected. 2. For QFX5100-48S-6Q with non-QFX5e image 18.4R2-S4, 19.1R3, 19.3R3, 19.4R3, and later releases are affected. 3. It is fixed in 20.3R3-S2, 21.1R3, 21.2R3, 21.3R2, 21.4R1, and all subsequent releases.
1628447802.1p BA classification might not work on mixed VC when interface has a DSCP and 802.1p classifier
Product-Group=junos
In a mixed (QFX5K and EX4300) VC (Virtual-Chassis) scenario, when traffic enters the VC on an EX4300, the classification for IP traffic (DSCP classifier) is working fine, but MPLS traffic is not correctly classified (802.1p classifier is NOT working and all traffic is classified as Best Effort) that might lead to incorrect QoS treatment for MPLS traffic.
PR NumberSynopsisCategory: QFX5100 Interface related issues
1633998The VCPs connected with the AOC cable might not come up after upgrading to 17.3 or later releases
Product-Group=junos
On QFX5100/EX4600 platforms with the Virtual Chassis (VC) scenario, if the Virtual Chassis Ports (VCPs) are connected through QSFP+40GE-AOC cable, post upgrading to 17.3 or later releases, VCPs might not come up or flap impacting VC functionality and services.
1638045Delay might be observed for the interfaces to come up after reboot/transceiver replacement
Product-Group=junos
On QFX5100/EX4600 Junos platforms with 2-member VC(Virtual Chassis) setup, after the device reboot or QSFP+-40G-SR4 SFP (small form-factor pluggable) replacement, the VC port might remain down and takes longer time (approximately 5-20min) to come up even if the cable is connected properly to the interface.
PR NumberSynopsisCategory: QFX5100 Platform optics
1561181The tunable optics SFP+-10G-T-DWDM-ZR does not work.
Product-Group=junos
On EX4600, EX4650, and QFX5110 switches with tunable optics SFP+-10G-T-DWDM-ZR, the configured wavelength value does not take effect when connecting two EX Series switches or QFX Series switches across a multiplexer (mux) using tunable optics SFP+-10G-T-DWDM-ZR.
PR NumberSynopsisCategory: QFX5100 Virtual Chassis
1601557Removing and adding VC ports might cause the FPC to reboot
Product-Group=junos
On QFX5100-24Q/QFX5100-48S/QFX5100-48T/QFX5100-96S Virtual Chassis (VC) setup, when the 10G VCP port is removed and added (logically/physically), the remaining 10G VCP ports are getting flap, causing the FPC to restart and the VC to lose the connection between members and rejoins to VC after sometime. Logically by using the commands "request virtual-chassis vc-port delete pic-slot port member " and "request virtual-chassis vc-port set pic-slot port member " to remove and add respectively. Physically by plugging and unplugging the optics corresponding to the VC port.
PR NumberSynopsisCategory: QFX5200/5110/5120/5210 Interface
1623283Interface on QFX52xx not coming up after swapping from 100G to 40G
Product-Group=junos
On QFX5200/5210/5220 series platforms, interface will not come up after replacing a 100G transceiver with a 40G one.
PR NumberSynopsisCategory: QFX5200/5110/5120/5210 Platfom issues
1630380QFX5k : Chassis Status LED doesn't work as document described
Product-Group=junosvae
On QFX5k series switch which is woking on 5e image, chassis status LED does not work properly. You may see unexpected state of SYS or MST LED on master or backup FPC.
PR NumberSynopsisCategory: RPD Interfaces related issues
1594981The label field for the EVPN Type 1 route is set to 1
Product-Group=junos
In the EVPN/VXLAN scenario, the label field for Type-1 route is not required but it is assigned 1 instead of 0, which is in conflict with the RFC7432.
PR NumberSynopsisCategory: RPD policy options
1537306The interface-routes rib-group policy does not work as expected in the VXLAN scenario
Product-Group=junos
On all Junos OS and Junos OS Evolved platforms in the VXLAN scenario, the interface-routes rib-group user-defined policy does not work as expected. This issue will cause all the direct routes to leak from the exported route table to the imported route table.
PR NumberSynopsisCategory: RPD route tables, resolver, routing instances, static routes
1590638The rpd might crash in scaled routing instances scenario
Product-Group=junos
On all Junos OS and Junos OS Evolved devices, when scaling routing instances are added, routing process might crash and generate core files (or dump files) after name index table space exhaustion. This might cause traffic loss.
1635009Multipath route getting formed for a VPN prefix due to incorrect BGP route selection logic
Product-Group=junos
On all Junos OS and Junos OS Evolved platforms running BGP, when a specific route is received from multiple places under a VRF, multipath route is getting formed even though the BGP route selection algorithm has the active route with higher local preference. Once multipath is formed, the traffic forwarding is happening based on that, and it may result in some traffic going to an unwanted path. Please refer to KB37775 [juniper.net] for more details.
PR NumberSynopsisCategory: Resource Reservation Protocol
1603613RSVP detour LSP might fail to come up when an LSR in the detour path goes down
Product-Group=junos
In a RSVP environment with fast-reroute enabled, when an LSR in a detour LSP goes down in particular scenario, the newly signaled detour path might be brought down and remain in incomplete state. This is due to a defect in RSVP-IO thread where it continues sending incorrect Path Refresh, which brings down the detour path.
PR NumberSynopsisCategory: SW PRs for SCBE3 fabric
1606296Fabric error might be seen when MPC10E to MPC2/MPC3/MPC4/MPC5/MPC6 based FPC fabric traffic is congested
Product-Group=junos
On the MX240/480/960 system with both MPC10E and MPC2/MPC3/MPC4/MPC5/MPC6 based FPCs are installed, when MPC10E sends high traffic to MPC4E or other mentioned cards as the destination, the destination line card will not be able to cope up with MPC10E traffic flow.
PR NumberSynopsisCategory: IPSEC functionality on M/MX/T ser
1631443The kmd might crash since the pkid requested memory leak happens on M/MX platforms
Product-Group=junos
In IPsec running M/MX platforms, in some rare cases (e.g., after rebooting router/upgrading MPC/SCB), the kmd (Key Manager Daemon) will crash due to pkid (handling Public Key Infrastructure function) requested memory leak. Then IPSec key negotiation service might be impacted and IPSec traffic loss might follow.
PR NumberSynopsisCategory: SRX branch platforms
1630886LLDP packets may be sent with incorrect source MAC for RETH/LAG child members
Product-Group=junos
On all platforms, when LLDP is run on child members of LAG/Redundant Ethernet (RETH) interfaces, LLDP packets may not be sent out with interface hardware address as source MAC. Instead, packets will be sent out using LAG/RETH interfaces MAC address. So, in case if the RETH/LAG interface MAC address changes, the source MAC address of LLDP packets will also change dynamically. Which will affect any service that relays on LLDP.
PR NumberSynopsisCategory: SRX5XX platform
1575231The fxp0 interface of an SRX550 in cluster might become unreachable from an external network
Product-Group=junos
On SRX550 configured with chassis cluster, fxp0 interfaces might not be reachable from external management interface when the fxp0 and redundant Ethernet(reth) interfaces are in separate routing instances. This is because there is no ARP entry for the reth interface in fxp0 ARP table. As a result of this, SRX cluster cannot be accessed from an external management network.
PR NumberSynopsisCategory: MPC7/8/9 Interface Issues
1626130Some Interfaces may not come online after line card reboot
Product-Group=junos
On all Junos platforms, when the line card is installed and if reboot is performed, some interfaces might remain down. This might impact traffic.
PR NumberSynopsisCategory: Stout cards (MPC8, MPC9) fabric issues
1617469MPC8E in 1.6T bandwidth mode may not work correctly
Product-Group=junos
If MPC8E is set in 1.6T bandwidth mode, it may not work correctly and the end result is that the MPC8E will not be able to see 1.6T throughput (as configured) and will see fabric drops at higher traffic rates. The 1.6T bandwidth fabric parameters are not getting applied to SFBs. https://kb.juniper.net/TSB18180 [juniper.net]
PR NumberSynopsisCategory: SRX-1RU platfom related protocol, QoS, filtering features et
1630990The srxpfe process might crash on SRX4600
Product-Group=junosvae
On SRX4600, a corruption in memory buffer (m_buf) might lead to srxpfe crash. Core files are generated and hardware monitoring failures might be observed when the process crashes.
PR NumberSynopsisCategory: ZT/YT pfe firewall software
1627986FPC might restart with syslog filter action configured
Product-Group=junos
On EVO-based PTX platforms and all MX series platforms with MPC10+, configuring syslog as a filter action may cause the FPC to restart.
PR NumberSynopsisCategory: ZT/YTpfe bridging, learning, stp, oam, irb software
1561934ARP resolution failure may occur in EVPN-VxLAN scenario
Product-Group=junos
On EX92xx/MX platforms with MPC10/11E installed, when a VxLAN bridge domain with "vlan-id none" is configured, ARP resolution from CE will have issues. ARP reply packets will carry an extra invalid VLAN tag.
1624804Traffic drop seen with egress features enabled on interface hosted on MPC10/MPC11
Product-Group=junos
On MX platforms with Advanced Forwarding Toolkit (AFT) based line cards (MPC10E, MPC11, LC9600) in L2 scenario, if the egress Next Hop (NH) is over an L2 interface hosted on the AFT based line card, enabling an egress feature on that interface might impact the traffic passing through it.
1638489Interoperability issue between legacy line cards and MPC10E/11E may cause incorrect load balancing over aggregate ethernet links
Product-Group=junos
On MX platforms, due to a software defect seen in interoperability scenarios on newer AFT-based MX cards (MPC10E and MPC11E), packets entering through legacy(non-AFT) card interfaces and exiting through AE interfaces via IRB may get incorrectly load balanced.
PR NumberSynopsisCategory: ZT/YT pfe l3 forwarding issues
1629100Packet loss might be seen intermittently if IPv6 Neighbor Discovery Protocol (NDP) entry is updated
Product-Group=junos
On EX9200 and MX240/480/960/2010/2020 platforms using MPC10 onwards with IPV6 is configured, packet loss might be seen intermittently if IPv6 Neighbor Discovery Protocol (NDP) entry is updated. (TSB18217 [juniper.net])
1635345Some packets might be dropped inside the l2circuit when the flow label is enabled
Product-Group=junos
On all Junos and EVO platforms, when Flow Label (FL) is enabled, if the egress Provider Edge (PE) is AFT-based FPC then it will receive the packets with Virtual-Circuit(VC) label, flow label, followed by Control Word (CW). If CW is not explicitly disabled then the Mpls-oam Next-Hop (NH) feature on egress PE looks into the CW to determine whether to punt the packet to RE or not. If the first nibble is 0x1 of CW means packets that were expected to be punted to RE which leads to packet drop.
PR NumberSynopsisCategory: Trio LU, IX, QX, MQ chip drivers, ucode & related SW
1626041Trio-based line cards might crash when Packet Forwarding Engine memory is hot-banking
Product-Group=junos
Trio-based line cards might crash when Packet Forwarding Engine memory is hot-banking. It is a rare issue.
PR NumberSynopsisCategory: Issues related to broadband edge apps (PPP, DHCP) on Trio ch
1637304FPC crash might be seen on all MX platforms with BBE subscriber
Product-Group=junos
FPC might crash on all MX platforms with Broadband Edge (BBE) subscribers and the traffic flowing through the impacted FPC will get affected.
PR NumberSynopsisCategory: Trio pfe stateless firewall software
1627908Unrealistic service accounting statistics might be reported due to firewall counter corruption
Product-Group=junos
On MX Series platforms with Broadband Edge (BBE) subscribers deployment, if filter with term of service-accounting action is applied to subscribers and subscribers are in active state, unrealistic service accounting statistics might be reported to the accounting server when service-accounting is deleted or deactivated from the filter configuration. Broadband Edge subscribers means 'Enhanced Subscriber Management' i.e., require system services subscriber-management enable to be configured.
PR NumberSynopsisCategory: Trio pfe bridging, learning, stp, oam, irb software
1643416RE switchover may result in traffic loss in a certain scenario
Product-Group=junos
On all Junos platforms that support MPLS with GRES and NSR enabled, on RE switchover through CLI or system reboot, traffic loss may happen.
PR NumberSynopsisCategory: Authentication, Authorization, Accounting, PAM (RADIUS/tacplus)
1589953The system generates an audit core file while changing TACACS and login user passwords
Product-Group=junos
The system might generate an audit core file (or dump file) while changing TACACS and login user passwords.
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1626721Junos upgrade may fail with error "configuration database size limit exceeded"
Product-Group=junos
On MX/M/T/PTX platforms, image validation during Junos upgrade may generate "configuration database size limit exceeded" error log resulting in upgrade failure.
1628046The process mgd may crash with errors if scripts synchronize is configured
Product-Group=junos
On every commit, when "system scripts synchronize" is configured, dob reference count increments (leaks). Over a period of time, juniper-config dop refcount increases infinitely and could reach the maximum value of 65535 and it overflows to zero. Once it hits zero, "insist error dop->do_refcount != 0" error is seen in the logs.
PR NumberSynopsisCategory: PTX/QFX100002/8/16 interface software
1600768CRC errors increase continuously after interface flap
Product-Group=junos
On PTX10008 and PTX10016 routers with LC1101, LC1102, or LC1103 line cards, interface flapping might cause the interface CRC errors to increase continuously. Then traffic loss might be seen. This is a rare timing issue.
PR NumberSynopsisCategory: MX10K platform
1623273chassisd memory leak may be seen after adding or removing an interface configuration
Product-Group=junos
On MX10008/10016 platforms, after adding/deleting interface in a loop, chassisd memory leak(approx. 24 byte of memory per commit) may be seen.
PR NumberSynopsisCategory: VMHOST platforms software
1605971VM host platforms might boot exactly 30 minutes after executing 'request vmhost halt' command
Product-Group=junos
On all VM host platforms running Junos OS Release 19.3R1 onwards, when 'request vmhost halt' is executed, the system reboots after exactly 30 minutes instead of maintaining the halt condition.
PR NumberSynopsisCategory: VNID L2-forwarding on Trio
1630163Scenario where within a VRF multiple VXLAN type-5 tunnels with same decap prefix are not handled on MPC10/11
Product-Group=junos
On MPC10/11 line cards, EVPN/VXLAN scenario where within a VRF multiple VXLAN type-5 tunnels with same decap prefix are created is not well handled, which might lead to traffic drop.
PR NumberSynopsisCategory: Virtual Router Redundancy Protocol
1635351VRRP route tracking for routes in VRF might not work if "chained-composite-next-hop ingress l3vpn" is used
Product-Group=junos
In L3VPN scenario with configured "routing-options forwarding-table chained-composite-next-hop ingress l3vpn" knob, if VRRP route tracking is used to track routes inside a VRF, and if such routes are with composite next hop, they might be marked as down even they are present in the VRF, hence the VRRP route tracking might not work properly.
 
 

20.2R3-S4 - List of Known issues

PR NumberSynopsisCategory: QFX PFE CoS
1631448The uplink interface remains down for a longer duration due to VXLAN scaled configuration
Product-Group=junos
On all Junos QFX5K platforms, with Virtual Extensible LAN (VXLAN) and the filters applied on the VXLAN interface both having scaled configuration, if the device reboots, the uplink interface might remain down for a longer duration, resulting in service impact.
PR NumberSynopsisCategory: ACX L2 related features
1628600Multicast traffic drop might be seen if IGMP snooping is enabled for VLAN
Product-Group=junos
On ACX5048, ACX5096, ACX4000 and ACX500 platforms, IGMP (Internet Group Management Protocol) snooping enabled for VLAN (virtual local area network) might drop multicast traffic. Please deactivate IGMP snooping for VLAN to recover from this issue.
PR NumberSynopsisCategory: access node control protocol daemon
1647180The 'show ancp subscriber details' CLI output for Access Loop Encapsulation tlv is updated
Product-Group=junos
Previously the Access Loop Encapsulation field would look like below. DSL Line Data Link : AAL5 DSL Line Encapsulation : Untagged Ethernet DSL Line Encapsulation Payload : PPOA LLC There is a text change to look as below after fix. Access Loop Encapsulation Data Link : AAL5 Access Loop Encapsulation Encapsulation1 : Untagged Ethernet Access Loop Encapsulation Encapsulation2 : PPOA LLC
PR NumberSynopsisCategory: a20a40 specific issue
1648850SCB reset with Error : zfchip_scan line = 844 name = failed due to PIO errors
Product-Group=junos
On SRX5000 series with SCB4, in rare occasions a Major Alarm may be raised for the SCB momentarily, while there is not actually a hardware error present. In a chassis cluster this will trigger an unexpected failover. This issue would be applicable for MX series with SCBE3 and EX9200 series with EX9200-SF3 as well.
PR NumberSynopsisCategory: This category is for Broadband Edge accounting related issue
1643077[technology/DT] [show] MX480 :: PFED CPU increased post ISSU and remains around 65-75% for 32k L2VPN sBNG services
Product-Group=junos
PFED CPU is going high as we are using COSD API to fetch the forwarding class to queueid for every IFL that is consuming lot of CPU. FIX: optimized to fetch the FC to queueid from COSD periodically (every 10 minutes) and update PFED internal datastructure which can be referred by every IFL to know the mapping
PR NumberSynopsisCategory: Class of Service
1650089Interface burst size becomes low in pfe, when 'rate-limit-burst' knob is removed
Product-Group=junos
When rate-limit-burst knob is deleted, burst size will fall back to the previously calculated burst size with the tx rate. In the above mentioned trigger, as the rate-limit-burst configs was present when the system is coming up, the burst size from the tx rate is not at all computed and when the user try to delete the knob, it is fall back to this un-computed burst size(default to 0). This is the reason for very small burst size configured to the rate limit queues. To fix this issue, we allow the burst size to be calculated even when global ratelimit knob is present and store it and use the burst size calculated from the global rate limit knob.
PR NumberSynopsisCategory: CFM
1536417FPC might core if CFM flap trap monitor feature in use
Product-Group=junos
The Flexible PIC Concentrator (FPC) might generate a core file (or dump file) if the flap-trap-monitor feature under "set protocols oam ethernet cfm performance-monitoring sla-iterator-profiles" is used and performance monitoring flap occurs.
PR NumberSynopsisCategory: Device Configuration Daemon
1643876[EX9200] vmcore dump and reboot due to panic after changing irb config in an evpn/vxlan environment
Product-Group=junos
Router may dump vmcore and gets rebooted when VGA ifa address gets replaced for family address and along with configuring VGA address as inactive in same commit.
PR NumberSynopsisCategory: ACX IFL, IFF creation
1638581L3 interface creation may fail on the ACX5448 and ACX710 platforms
Product-Group=junos
On the ACX5448 and ACX710 platforms, Layer 3 interface creation may fail due to a base MAC address programmed on the PFE. As a result, the simplest symptom is ping failure.
PR NumberSynopsisCategory: Covers Application classification workflows apart from custo
1632205Signature package update may fail and the appid process may crash on SRX devices
Product-Group=junos
On SRX platforms, with a sig-pack update if any application is moved to DEPRICATED and if that application was part of any custom group, signature upgrade may fail. Due to this sometimes the appid process may crash.
PR NumberSynopsisCategory: EVPN Layer-2 Forwarding
1613201IRB proxy-arp unrestricted might not work if EVPN/l2alm proxy is enabled
Product-Group=junos
On all Junos platforms, if Ethernet Virtual Private Network (EVPN)/Layer 2 Address Learning Manager (l2alm) proxy is enabled, Integrated Routing and Bridging (IRB) proxy-arp unrestricted might not work and impact the traffic.
PR NumberSynopsisCategory: EX4400 platform
1614145EX4400-48MP - VM cores and VC split maybe observed with multicast scale scenario
Product-Group=junos
EX4400-48MP - VM cores and VC split maybe observed with multicast scale scenario
PR NumberSynopsisCategory: EX optics issues
1611772Traffic stops when traffic is switching from one LAG member to another member in case of MACSEC is configured
Product-Group=junos
During config change of MACSEC on LAG, LAG members (port) is reinitializing the STP from fresh and due to STP state of port is getting modifying, it went to disable state and traffic loss occurred.
PR NumberSynopsisCategory: Express PFE including evpn, vxlan
1649841In Junos version 20.2R3-S3 and EVPN-VXLAN environment non-VXLAN packet can get drop if VXLAN and non-VXLAN traffic are sharing the same ECMP next-hop.
Product-Group=junos
In Junos version 20.2R3-S3 and EVPN-VXLAN environment non-VXLAN packet can get drop on QFX10002 & QFX10008 if VXLAN and non-VXLAN traffic are sharing the same ECMP next-hop.
PR NumberSynopsisCategory: Express PFE MPLS Features
1618507Traffic loss might be observed with some MPLS labels in multipath BGP scenarios
Product-Group=junos
On all PTX platforms, when a Provider Edge (PE) router is configured with multipath, traffic loss might be seen even though the link is up. After this PR, a new knob "no-ifl-based-frr-for-inh-primary" can be applied under "forwarding-options" to avoid such issues.
1628196EAPol packets over Layer 2 circuit may get dropped at the tunnel start
Product-Group=junos
On all PTX Series routers in the Layer 2 circuit scenario, when the "l2circuit-control-passthrough" option is enabled, Extensible Authentication Protocol over LAN (EAPoL) packets might not go over the Layer 2 circuit as expected.
PR NumberSynopsisCategory: Flow-tap software
1647179DTCP radius-flow-tap fails to program PFE when trigger X-NAS-Port-Id exceeds 48 character length.
Product-Group=junos
DTCP radius-flow-tap fails to program PFE when trigger X-NAS-Port-Id exceeds 48 character length.
PR NumberSynopsisCategory: Express ASIC interface
1606008Link flaps might be observed momentarily on PTX5000 routers
Product-Group=junos
On PTX5000 routers with QSFP-100GBASE-LR4 optics, after a software upgrade, link flaps might be observed momentarily due to a firmware upgrade issue. This issue might cause traffic impact.
PR NumberSynopsisCategory: Kernel software for AE/AS/Container
1641988The VMcore might be observed on EX platforms in rare scenario
Product-Group=junos
On EX platforms, the Routing Engine (RE) might get crashed and result in VMcore, if the kernel sends a request to PFE for fetching the statistics of an Aggregated Ethernet (AE) with more than one member link. This issue appears when the member link gets lost for certain reasons in background and at the same time the kernel's request arrives. Since AE member link has lost, PFE might not send statistics response to kernel within 10 seconds(default time) and error might be returned. This invalid memory access might result in RE crash by generating VMcore. This could be a rare case scenario.
PR NumberSynopsisCategory: Category for JET(JUNOS Extension Toolkit) related issues
1643070After RE switchover, jsd might crash
Product-Group=junos
If the Juniper Extension Tookit is in use to interact with Junos, the JET service process (jsd) may generate a crash after GRES.
PR NumberSynopsisCategory: High Availability/NSRP/VRRP
1655527When performing In-Service Software Upgrade (ISSU) on a cluster with non-reth interfaces, these interfaces might not come up, leading to traffic disruption
Product-Group=junos
When performing In-Service Software Upgrade (ISSU) on a cluster with non-reth interfaces, these interfaces might not come up, leading to traffic disruption
PR NumberSynopsisCategory: User Firewall related issues
1637548Unable to connect to domain controller on installing Microsoft KB update
Product-Group=junos
On all SRX platforms, when the User Identification feature is used with Active Directory, after the Domain Controller server installs updates related to Microsoft's KB article KB5004442 [juniper.net], SRX is no longer able to connect to it.
PR NumberSynopsisCategory: IPSEC/IKE VPN
141633419.1R1: ISSU: During ISSU from 18.4R1 to 19.1, traffic through IPSEC VPN fails.
Product-Group=junos
On SRX5400, SRX5600, and SRX5800 devices, during in-service software upgrade (ISSU), the IPsec tunnels flap, causing a disruption of traffic. The IPsec tunnels recover automatically after the ISSU process is completed.
1603670Flowd process might crash and generate a corefile after upgrade
Product-Group=junos
After performing upgrade on the Siege SRX-Series devices (SRX300, SRX320, SRX340, SRX345 and SRX550M), device might get stuck in boot loop and the flowd process might crash and generate a corefile.
PR NumberSynopsisCategory: PFE infra to support jvision
1622073Telemetry/jvision, system_id formate of AFT-MPC(MPC10E) is not align with non-AFT MPCs
Product-Group=junos
System_id formate of AFT-MPC(MPC10E) is not align with non-AFT MPCs
PR NumberSynopsisCategory: Layer 2 Control Module
1629011Traffic drop might be reported on the interface after reboot or power cycle
Product-Group=junos
On Junos and EVO platforms, after reboot or power cycle, aggregated ethernet (AE) interfaces will have spanning tree protocol (STP) state discarding after the box comes up. It might cause traffic drop on the interface.
PR NumberSynopsisCategory: IPv6/ND/ICMPv6 issues
1631607ipv6 host route prefix match disappear from 'forwarding-table' after a ping test, ping continues to work, forwarding table entry is not shown. No impact in traffic.
Product-Group=junos
IPv6 route resolutions for ipv6 hosts is missing from the 'route forwarding-table' after pinging hosts within the ip prefix.
PR NumberSynopsisCategory: OSPF routing protocol
1636028RPD memory leak on OSPF SR routers when deploy in a network with mixed OSPF SR/Non-SR router
Product-Group=junos
When mixing OSPF Segment Routing (SR) routers with non-SR routers, you may see memory leak on the SR routers.
PR NumberSynopsisCategory: Chassis mgmt for all QFX systems - chassis MIB, alarms, CLI
1603588Chassisd generates "Cannot read hw.chassis.startup_time value: m" every 5 seconds on qfx10008 and qfx10016
Product-Group=junos
The "Cannot read hw.chassis.startup_time value:m" error log is generated every 5 seconds in the output by "show log chassisd" on qfx10008 and qfx10016. This is a cosmetic message. There is no impact to the system.
PR NumberSynopsisCategory: Interface related issues. Port up/down, stats, CMLC , serdes
1327811The IPv6 transit statistics counter does not work.
Product-Group=junos
The chip has VLAN-based logical interface statistics. Since for a given logical interfaces on both IPv4 and IPv6 use the same VLAN, statistics will count both V4 and V6 together. There is no way to separately count them. Hence, "IPv6 transit statistics" is always 0. However, the total transit statistics (IPv4 + IPv6) will be displayed under "Transit statistics".
PR NumberSynopsisCategory: QFX5K hostpath
1630201LACP timeout might be observed during high CPU utilization
Product-Group=junos
On QFX5100 switches, when the CPU utilization (Routing Engine and FPC) is 85 percentage or more and there are multiple Network Configuration Protocol (NETCONF) sessions running or SNMP polling is happening over multiple sessions simultaneously, the LACP session configured in fast mode might timeout.
PR NumberSynopsisCategory: QFX L2 PFE
1560086On the QFX5200 line of switches, the pseudorandom binary sequence (PRBS) test fails for 100GbE interfaces with the default settings.
Product-Group=junos
On the QFX5200 line of switches, the pseudorandom binary sequence (PRBS) test fails for 100GbE interfaces with the default settings.
PR NumberSynopsisCategory: QFX10008/16 QFX10002 linecard, serdes and uboot
1632440The interface might remain in the "UP/UP" state even the interface is admin disabled
Product-Group=junos
On the QFX10002/QFX10008/QFX10016 platforms, if reboot the FPC with interface admin disabled configuration, the interface might remain in the "UP/UP" state.
PR NumberSynopsisCategory: QFX10008/16 QFX10002 Ultimat/Elit platform related issues -
1597479The process dcpfe/FPC crash may be observed on the QFX10000 series platforms in a rare case
Product-Group=junosvae
On the QFX10000 series platforms, the process dcpfe/FPC crash may be observed in boot time if rebooting the devices.
PR NumberSynopsisCategory: KRT Queue issues within RPD
1623170BGP Flowspec may not shows counters for matching IPv6 firewall filter
Product-Group=junos
Under investigation - When installing an IPv6 firewall filter using BGP flowspec, matching traffic counters may show "0" values.
PR NumberSynopsisCategory: RPD policy options
1616167The rpd process might get stuck at 100% when EVPN vrf-target is enabled and after any configuration change
Product-Group=junos
On all Junos and EVO platforms with EVPN (Ethernet VPN)/EVPN-VXLAN (Virtual Extensible LAN Protocol) implemented, any configuration (related/unrelated) change with the knobs 'vrf-target auto' and/or 'protocols evpn vni-options vni vrf-target ' being enabled might result in CPU spike and thus, rpd (routing protocol process) gets stuck at 100%. Traffic could be blackholed during the incident happening and could be back to normal once CPU usage is decremented after an interval.
1646603Existing routing policies might change when global default route-filter walkup is changed
Product-Group=junos
When "set policy-options default route-filter walkup" configuration is changed( add/delete), existing routing-policies might change and all the existing "from" matching criteria will be removed from the routing-policies in the policy-db.
PR NumberSynopsisCategory: RPM and TWAMP
1522488rmopd reports false TCP errors in the log messages: RMOPD_TWAMP_SOCKOPT_FAILURE setsockopt(TCP_KEEP.*) failed, error: Invalid argument. This is cosmetic issue.
Product-Group=junos
rmopd reports false TCP errors in the log messages: RMOPD_TWAMP_SOCKOPT_FAILURE setsockopt(TCP_KEEP.*) failed, error: Invalid argument. This is cosmetic issue. The issue is fixed in Junos releases 21.1R1 and newer.
 

Modification History

First publication 2022-04-11